diff --git a/cmd/claimer/main.go b/cmd/claimer/main.go index 272dad675..c338ccf7a 100644 --- a/cmd/claimer/main.go +++ b/cmd/claimer/main.go @@ -24,6 +24,7 @@ var ( dryRun = flag.Bool("dry-run", false, "print what would be done without emitting SQL") verbose = flag.Bool("v", false, "log pagination progress") apply = flag.Bool("apply", false, "execute the emitted SQL against D1 via wrangler") + yes = flag.Bool("yes", false, "required together with -apply as a destructive-action gate") local = flag.Bool("local", false, "apply against the local D1 instead of remote") d1Name = flag.String("d1", "tangled-sites", "D1 database name for wrangler d1 execute") ) @@ -173,6 +174,11 @@ func main() { os.Exit(1) } + if *apply && !*yes { + logger.Error("-apply is destructive for the target D1 tables; pass -yes to confirm") + os.Exit(1) + } + if *apply && len(rows) > 0 { args := []string{"wrangler", "d1", "execute", *d1Name, "--file", absOut} if !*local { @@ -221,9 +227,6 @@ func sitesDir() string { return "sites" } -// handleClaimsSQL wraps the permanent-handle claim statements; only tngl.sh -// handle domains are emitted (the loop guard above already enforces this, the -// wrapper keeps the invariant local to the emission). func handleIsPermanent(handle string) bool { return strings.HasSuffix(handle, ".tngl.sh") }